Cicada 3301 Ransomware
Summary
Cybersecurity experts have analyzed a new ransomware variant named the Cicada 3301, which shares traits with the now-discontinued BlackCat (also known as ALPHV) operation. The Cicada 3301 primarily targets small to medium-sized businesses (SMBs), leveraging vulnerabilities as its initial access point through opportunistic attacks. Besides maintaining a built-in list of excluded files and directories during the encryption process, the ransomware targets a total of 35 file extensions - sql, doc, rtf, xls, jpg, jpeg, psd, docm, xlsm, ods, ppsx, png, raw, dotx, xltx, pptx, ppsm, gif, bmp, dotm, xltm, pptm, odp, webp, pdf, odt, xlsb, ptox, mdf, tiff, docx, xlsx, xlam, potm, and txt. Researchers have also uncovered additional tools like EDRSandBlast that weaponize a vulnerable signed driver to bypass EDR detections, a practice also adopted by the BlackByte Ransomware group in the past. Provide you with proof that the data has been stolen; Help you rebuild your infrastructure and prevent similar attacks in the future; Our reputation is of paramount importance to us.